Job Summary:
The Security and Compliance Lead is responsible for overseeing security governance, compliance management, and risk mitigation activities across the IT environment. The role ensures adherence to FedRAMP-related requirements, protection of Federal Tax Information (FTI), vulnerability management processes, and compliance with frameworks such as SOC 2 and ISO standards. The individual works closely with technical, operational, audit, and business teams to maintain a strong security posture, support regulatory requirements, and drive continuous compliance improvements.
Key Responsibilities:
- Lead the organization's security and compliance programs to ensure adherence to regulatory, contractual, and organizational requirements.
- Manage compliance activities related to FedRAMP controls and security requirements.
- Ensure proper handling, protection, and monitoring of Federal Tax Information (FTI) in accordance with applicable regulations and policies.
- Develop, maintain, and monitor security policies, standards, procedures, and compliance controls.
- Oversee vulnerability management processes, including vulnerability assessments, remediation tracking, reporting, and risk mitigation.
- Coordinate periodic security reviews, risk assessments, and compliance evaluations.
- Support SOC 2, ISO 27001, and other compliance audits by collecting, validating, and maintaining required evidence and documentation.
- Track and manage audit findings, compliance gaps, corrective actions, and remediation plans.
- Collaborate with infrastructure, application, security, and operations teams to implement and maintain security controls.
- Monitor regulatory changes and assess their impact on security and compliance obligations.
- Prepare compliance reports, risk dashboards, and executive updates for management and stakeholders.
Required Qualifications:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field.
- 7+ years of experience in Information Security, Risk Management, Compliance, Audit, or Governance roles.
- Strong knowledge of FedRAMP security requirements and regulatory compliance frameworks.
- Experience handling and protecting Federal Tax Information (FTI) and supporting regulated environments.
- Hands-on experience managing vulnerability assessment, remediation, and risk management programs.
- Experience supporting SOC 2, ISO 27001, and similar regulatory or security compliance audits.
- Knowledge of security governance, risk management, security controls, and compliance monitoring.
- Familiarity with security tools, vulnerability management platforms, and audit management processes.
- Strong analytical, problem-solving, and risk assessment skills.
- Excellent communication, documentation, and stakeholder management abilities.
- Experience working with auditors, regulators, customers, and cross-functional technology teams.